README revision 7c478bd95313f5f23a4c958a745db2134aa03244
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe#
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe# CDDL HEADER START
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe#
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe# The contents of this file are subject to the terms of the
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe# Common Development and Distribution License, Version 1.0 only
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe# (the "License"). You may not use this file except in compliance
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe# with the License.
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe#
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe# You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe# or http://www.opensolaris.org/os/licensing.
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe# See the License for the specific language governing permissions
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe# and limitations under the License.
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe#
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe# When distributing Covered Code, include this CDDL HEADER in each
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe# file and include the License file at usr/src/OPENSOLARIS.LICENSE.
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe# If applicable, add the following below this CDDL HEADER, with the
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe# fields enclosed by brackets "[]" replaced with your own identifying
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe# information: Portions Copyright [yyyy] [name of copyright owner]
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe#
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe# CDDL HEADER END
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe#
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe#
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe# Copyright 2004 Sun Microsystems, Inc. All rights reserved.
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe# Use is subject to license terms.
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe#
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe#pragma ident "%Z%%M% %I% %E% SMI"
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe Notes Regarding Modification of generic_open.xml
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard LoweAny changes made to generic_open.xml will need to be considered for
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Loweinclusion in generic_limited_net.xml, the "Secure By Default" (see
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowehttp://solsec.eng.sun.com/sbd/) profile. The details are discussed
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowein PSARC/2004/781:
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe ...
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe The generic_limited_net profile explicitly disables all
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe smf(5) converted inetd services that are not required to
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe run the window system, SVM, or vold. It retains ssh and
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe X remote login as the remote login methods available.
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe ...
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard LoweIn general, _any_ service that allows inbound net access should be
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Loweadded to generic_limited_net and disabled, unless its activation
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowehas been:approved by SBD.
10d63b7db37a83b39c7f511cf9426c9d03ea0760Richard Lowe